Studiocms is a content-management platform with a narrowly focused product footprint that has attracted attention within the CMS landscape. Its vulnerability profile centers recurrently on authorization and privilege-management weaknesses—including user-controlled authorization keys, improper privilege boundaries, and weak password-recovery mechanisms—that reflect the access-control complexity inherent to multi-user publishing systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Studiocms over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30944HIGH StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated use | Mar 10, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-30945HIGH StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authentica | Mar 10, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-32103HIGH StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset-link endpoint allows any authe | Mar 11, 2026 | 7.2 | 23 | NO | NO |
CVE-2026-32106HIGH StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API createUser endpoint uses string-based rank checks that only bloc | Mar 11, 2026 | 7.2 | 22 | NO | NO |
CVE-2026-32101MEDIUM StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() function is declared async (returns P | Mar 11, 2026 | 6.3 | 22 | NO | NO |
CVE-2026-24134MEDIUM StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authorization (BOLA) vulnerability in t | Jan 28, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-32104MEDIUM StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNotifications endpoint accepts a user ID from the request paylo | Mar 11, 2026 | 5.4 | 19 | NO | NO |
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `getUsers` endpoint in StudioCMS uses the attacker-controlled `r | Mar 18, 2026 | 2.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Studiocms.
Media articles that mention a CVE ID that affects a product developed by Studiocms — matched by CVE ID, not by vendor name.